MD Systems maintains a narrowly scoped portfolio focused on the Simplenews product, a Drupal-based newsletter and mailing-list module embedded in many Drupal installations. The recorded vulnerability exposure reflects application-level issues typical of web-based content and subscription handling in Drupal ecosystems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Md Systems over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-13241MEDIUM Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. | Jul 10, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-13240MEDIUM Missing Authorization vulnerability in Drupal Paragraphs allows Forceful Browsing. This issue affects Paragraphs versions: from 0.0.0 to 1.21.0. | Jul 10, 2026 | 6.5 | 29 | NO | NO |
CVE-2012-2724MEDIUM The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers w | Jan 9, 2020 | 5.3 | 20 | NO | NO |
CVE-2013-4447MEDIUM Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrar | Nov 1, 2013 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Md Systems.
Media articles that mention a CVE ID that affects a product developed by Md Systems — matched by CVE ID, not by vendor name.